India’s CSAM Reporting Gap Explained: POCSO Duties, CyberTipline and Platform Liability
Why in News?
The National Human Rights Commission (NHRC) has sought reports from the Ministry of Electronics and Information Technology, the Ministry of Information and Broadcasting and Delhi Police after paid Instagram advertisements allegedly directed users towards channels offering child sexual abuse material. The controversy has brought into focus mandatory reporting under Section 19 of the POCSO Act, intermediary liability under the Information Technology framework, the CyberTipline reporting system, artificial-intelligence-driven content recommendation and the large gap between online abuse alerts and effective criminal investigation.
Key Points
The controversy arose from allegations that paid advertisements appearing on Instagram used sexually abusive search terms and directed users towards Telegram channels allegedly offering child sexual abuse material. NHRC subsequently sought point-wise Action Taken Reports from MeitY, the Ministry of Information and Broadcasting and Delhi Police.
NHRC raised two significant regulatory questions: whether the platform complied with the mandatory reporting obligation contained in the Protection of Children from Sexual Offences Act, 2012, and whether an online platform can continue to be treated merely as a passive “intermediary” when its algorithms and AI systems participate in recommendation, amplification, editing, monetisation or distribution of content.
Section 19 of the POCSO Act requires a person who apprehends that an offence under the Act is likely to be committed, or knows that such an offence has been committed, to report the matter to the Special Juvenile Police Unit or local police. The Act separately prescribes punishment for failure to report or record certain offences.
India received around 1.9 million CyberTipline reports in 2025, according to figures cited in the report, but only a much smaller number ultimately translated into police cases. This exposes a major enforcement bottleneck between automated detection, verification, jurisdiction identification and criminal investigation.
CyberTipline reports originate when technology companies report suspected child sexual abuse and exploitation to the US-based National Center for Missing & Exploited Children (NCMEC). Reports linked to India are routed to Indian authorities and processed through agencies including the NCRB and the Indian Cyber Crime Coordination Centre (I4C).
Investigators use account information, IP logs, email addresses, phone numbers and digital hash values to identify the location, user and material involved. A hash functions as a digital fingerprint that can help determine whether two files are identical or correspond to previously identified illegal material.
India’s principal legal provisions against online sexual exploitation of children include Sections 13-15 and 19-21 of the POCSO Act and Section 67B of the Information Technology Act, 2000. Section 67B addresses electronic publication, transmission and other specified forms of online sexual exploitation involving children.
The Supreme Court in Just Rights for Children Alliance v. S. Harish clarified in 2024 that Section 15 of POCSO can apply even where illegal material is not physically downloaded if the accused exercises sufficient control over it. The Court recognised the doctrine of constructive possession and emphasised mandatory reporting obligations.
The Court also recommended moving away from the expression “child pornography” because it can obscure the reality that the material records sexual exploitation and abuse of a child. The more appropriate policy terminology is Child Sexual Exploitative and Abuse Material (CSEAM) or Child Sexual Abuse Material (CSAM).
Under the Information Technology Act, intermediaries may obtain conditional protection from liability under Section 79, but this protection depends upon compliance with statutory conditions and due diligence. The IT Rules, 2021 impose additional responsibilities relating to unlawful content, grievance handling and cooperation with lawful government directions.
The 2026 amendments to the IT Rules additionally require intermediaries offering tools for synthetically generated information to deploy reasonable technical measures to prevent creation or dissemination of illegal material, including child sexual exploitative and abuse material.
The issue is therefore wider than a single social-media advertisement. It concerns child protection, intermediary accountability, algorithmic governance, criminal investigation, cross-border digital evidence, AI-generated abuse material and the ability of law-enforcement institutions to convert millions of automated alerts into actionable cases.
Explained
What is Child Sexual Abuse Material?
Meaning: Child Sexual Abuse Material or CSAM refers to visual or other material depicting the sexual abuse or exploitation of a child. Indian law still uses statutory expressions such as “pornographic material involving child” in the POCSO Act, but child-rights institutions increasingly prefer CSAM or CSEAM because the content represents evidence of abuse rather than consensual pornography.
Child under POCSO: The Act defines a child as any person below 18 years of age.
Why terminology matters: The Supreme Court in Just Rights for Children Alliance v. S. Harish observed that the expression “child pornography” can trivialise the exploitative nature of such material and recommended terminology reflecting child sexual exploitation and abuse.
What exactly triggered the latest controversy?
Paid advertising allegation: The case concerns paid Instagram advertisements which allegedly used abusive search terms and redirected users towards Telegram channels where sexual abuse material involving children was allegedly offered.
Platform-review question: According to the report considered by NHRC, the advertisements had passed Meta's advertising-review systems and remained available until external attention was drawn to them.
Regulatory significance: This raises a more serious issue than simply whether illegal content was uploaded. A paid advertisement passes through an organised commercial and automated system involving approval, targeting, recommendation and monetisation.
NHRC intervention: NHRC therefore asked whether statutory reporting duties were followed and whether a platform deeply involved in automated recommendation and monetisation should always receive the same treatment as an intermediary that merely transmits third-party information.
What is the National Human Rights Commission and why can it intervene?
Statutory institution: NHRC is established under the Protection of Human Rights Act, 1993.
Role: It can inquire into alleged violations of human rights, seek reports from public authorities, make recommendations and take suo motu cognisance of serious reported violations.
Child-rights dimension: Online circulation or commercialisation of sexual abuse material affects the child's dignity, privacy, bodily integrity and protection from exploitation.
Previous intervention: NHRC had already issued an advisory specifically concerning protection of children against production, distribution and consumption of CSAM and had earlier taken cognisance of reports of a sharp increase in such material on social media.
What is the POCSO Act?
Purpose: The Protection of Children from Sexual Offences Act, 2012 is India's principal special law dealing with sexual offences against persons below 18 years.
Gender-neutral law: The statutory definition of “child” is gender neutral.
Major offences: The Act covers penetrative sexual assault, sexual assault, sexual harassment and use of children for pornographic purposes.
Special procedure: It establishes child-friendly procedures for reporting, recording evidence and trial and provides for designated Special Courts.
Which provisions of POCSO are particularly important for online CSAM?
Section 13: It deals with use of a child for pornographic purposes.
Section 14: It prescribes punishment for using a child for pornographic purposes.
Section 15: It deals with storage or possession of pornographic material involving a child under different circumstances and with different forms of criminal intent.
Section 19: It establishes mandatory reporting where a person apprehends that a POCSO offence is likely to be committed or has knowledge that one has been committed.
Section 20: It imposes specific reporting obligations on media, hotels, lodges, hospitals, clubs, studios and photographic facilities in circumstances specified by the Act.
Section 21: Failure to report or record an offence can itself attract punishment.
Why is Section 19 of POCSO central to the present controversy?
Mandatory duty: Section 19 is a mandatory-reporting provision. It does not merely encourage voluntary reporting.
A person who has knowledge that an offence under POCSO has been committed, or apprehends that such an offence is likely to be committed, must provide information to the Special Juvenile Police Unit or local police.
NHRC's concern: The Commission has effectively asked whether detection of suspected abuse material inside a company's systems resulted in the legally required report.
Internal action is different: Removing material, suspending an account, exchanging emails internally or applying a company's community standards cannot necessarily be treated as a substitute for the statutory reporting obligation. This distinction was central to NHRC's questions in the current matter.
Governance implication: Digital platforms may have private moderation systems, but statutory criminal-law obligations operate independently of a platform's own rules.
Does possession or viewing of CSAM constitute an offence?
Supreme Court clarification: The answer depends upon the circumstances, possession, control and intention prescribed by Section 15 of POCSO.
In Just Rights for Children Alliance v. S. Harish, the Supreme Court rejected a narrow interpretation under which only physical downloading or permanent storage would matter.
Constructive possession: A person can exercise control over digital material even when it is not permanently downloaded. For example, a person intentionally accessing material online may still possess sufficient control to view, forward, save or manipulate it.
Mens rea remains relevant: Section 15 contains distinct offences involving different mental elements, such as intention to share, transmit, display, distribute or obtain commercial benefit. The judgment should therefore not be reduced to the oversimplified claim that every accidental exposure to illegal material automatically leads to criminal liability.
What does Section 67B of the Information Technology Act cover?
Electronic offence: Section 67B of the Information Technology Act, 2000 specifically addresses material depicting children in sexually explicit acts in electronic form.
Broader coverage: The Supreme Court has described Section 67B as a comprehensive provision covering several forms of online sexual exploitation, including electronic dissemination and other forms of online conduct involving children.
Child threshold: For this provision, a child means a person who has not completed 18 years of age.
Special Courts: Section 28(3) of POCSO enables POCSO Special Courts to try offences under Section 67B of the IT Act when they involve sexually explicit material depicting children.
What is an “intermediary” under India's digital law?
Basic idea: An intermediary is an entity that receives, stores or transmits electronic records on behalf of another person or provides services connected with such records.
Examples can include social-media services, internet service providers, online marketplaces and other digital platforms depending on their functions.
Traditional model: The intermediary concept was originally built around the idea that a platform may facilitate communication without itself being the creator of every piece of third-party content.
Safe harbour: Section 79 of the IT Act provides conditional exemption from liability for intermediaries in relation to certain third-party information, subject to statutory requirements.
Is Section 79 an absolute immunity for social-media companies?
No: Safe harbour is conditional, not absolute.
Due diligence: The intermediary must comply with the IT Act and applicable rules, including prescribed due-diligence obligations.
Knowledge and unlawful conduct: Protection can be affected where statutory conditions for safe harbour are not satisfied or where the intermediary itself participates in unlawful conduct in a manner falling outside the protection.
UPSC distinction: “Intermediary status” and “automatic immunity” are not synonymous.
Why has artificial intelligence complicated intermediary liability?
Traditional internet model: Earlier legal frameworks often imagined a relatively passive platform that stores or transmits content created by users.
Modern platform: Large platforms increasingly rank feeds, recommend content, target advertisements, generate captions, optimise posting times, suggest audiences and monetise engagement.
NHRC question: If algorithms participate substantially in generation, recommendation, amplification or monetisation, the line between passive host and active content participant becomes more difficult to draw.
Legal uncertainty: Merely using algorithms does not automatically make a platform a “publisher” in every case. What matters is how deeply the platform participates in the unlawful content and how existing statutory requirements apply.
Mains issue: India's digital-governance framework increasingly has to regulate not just uploaded content but algorithmic conduct.
What are the IT Rules, 2021?
Full name: Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
Purpose: They prescribe due-diligence and grievance-related obligations for intermediaries and additional obligations for certain categories of intermediaries and digital-media entities.
Updated framework: MeitY's consolidated rules have undergone several amendments, including major updates concerning synthetically generated information in 2026.
Relevance to CSAM: The regulatory framework requires intermediaries to act responsibly in relation to unlawful content, respond to lawful orders and operate appropriate grievance and compliance mechanisms.
What changed in 2026 regarding AI-generated content?
Synthetically generated information: The amended rules address content generated or altered through digital systems, including artificial intelligence.
Technical safeguards: Intermediaries providing tools capable of generating or modifying synthetic information must deploy reasonable and appropriate technical measures to prevent users from generating specified unlawful material.
Child protection: The updated rule expressly includes child sexual exploitative and abuse material among prohibited categories.
Why important: The challenge is no longer confined to detecting known abusive images. Generative AI can potentially create new synthetic abusive material which may not match existing databases of known illegal files.
What is the CyberTipline?
International reporting mechanism: CyberTipline is operated by the US-based National Center for Missing & Exploited Children (NCMEC).
Technology-company reports: Online platforms report suspected child sexual exploitation activity to NCMEC.
India-linked alerts: Where the report appears connected to India, relevant information is transmitted into India's law-enforcement system.
Scale: The newspaper report states that India received around 1.9 million CyberTipline reports in 2025.
Critical caution: A CyberTipline report is an alert, not proof that the person associated with an account has committed an offence. Verification and investigation remain necessary.
How does a CyberTipline report reach Indian police?
Stage 1 — Platform detection: A technology company identifies suspected child sexual abuse or exploitation activity.
Stage 2 — NCMEC: The platform sends the information to NCMEC's CyberTipline.
Stage 3 — India routing: India-linked reports enter the Indian enforcement system.
Stage 4 — Central processing: Reports are processed through agencies including the National Crime Records Bureau (NCRB) and Indian Cyber Crime Coordination Centre (I4C), both associated with the Union Ministry of Home Affairs.
Stage 5 — State/district verification: The report is assigned to the relevant State, district, cyber unit or police station.
Stage 6 — FIR and investigation: Investigators identify jurisdiction, verify the material and determine whether the statutory ingredients of an offence appear to be satisfied.
This multi-stage chain is one reason why a very large number of automated reports does not translate directly into an equivalent number of FIRs.
What is I4C?
Institution: The Indian Cyber Crime Coordination Centre (I4C) operates under the Ministry of Home Affairs.
Purpose: It provides a national-level framework for coordinated action against cybercrime.
Citizen interface: The National Cyber Crime Reporting Portal allows people to report cybercrime, including complaints relating to women and children. The portal specifically provides reporting facilities for online CSAM and sexually explicit material.
UPSC relevance: I4C is an important internal-security and cyber-governance institution.
What is a digital hash value and why is it important?
Digital fingerprint: A hash value is a mathematical output generated from a digital file.
Identification: Even a large video or image can be represented by a comparatively short hash.
Known CSAM databases: If authorities or technology companies have already identified an illegal file, its hash can be used to detect matching copies without repeatedly relying only on human viewing.
Investigative value: Investigators can compare the hash in a CyberTipline report with the hash generated from material recovered from a device to determine whether the files correspond.
Limitation: A materially altered, cropped or synthetically generated image may produce a different conventional hash. This is one reason detection technologies must continue evolving.
Why do millions of reports not automatically lead to millions of FIRs?
Reports are leads: Some alerts contain substantial account, IP and file information; others may be incomplete.
Jurisdiction: Investigators must identify the State, district or police station having jurisdiction.
Age verification: A crucial question is whether the person depicted is actually below 18.
Material verification: Police must establish that the content prima facie falls within the statutory offence.
User attribution: An IP address, SIM card or device does not always establish which individual was operating an account at the relevant time.
Cross-border platforms: Data may be controlled by companies or infrastructure outside India.
Encryption: End-to-end encryption and closed groups may make detection more difficult.
Volume: Extremely high volumes of reports can overwhelm specialist cybercrime units.
The Indian Express report notes that variability in the quality of CyberTipline reports is one reason not every alert proceeds to an FIR.
What did NCRB data reveal about cybercrimes against children?
Registered cases: According to NCRB's 2024 figures cited in the report, 1,238 cybercrime cases against children were registered under the Information Technology Act.
Sexually explicit material: Of these, 1,099 cases involved publication or transmission of sexually explicit material depicting children—nearly nine in ten of the IT Act cases against children reported in that category.
Important interpretation: CyberTipline alerts and NCRB registered cases are not directly comparable datasets. One records digital alerts; the other records criminal cases accepted into the policing system.
The large numerical difference nonetheless illustrates the filtering and investigation burden involved.
How is the identity of an offender established in a digital CSAM case?
Account records: Platforms may provide account-creation information and login data.
IP address: Investigators may link online activity to an internet connection.
Telecom information: SIM ownership and call-data information may help identify the person associated with a device or account.
Financial trail: Payments made for illegal material can be useful evidence, particularly where UPI or bank transactions are involved.
Device forensics: Phones, computers and storage devices can reveal downloads, communication history, browser artefacts and other evidence.
Cross-verification: Strong cases generally rely on several independent data points rather than one IP address or SIM record alone.
What is the role of electronic evidence in such cases?
Evidence-intensive offences: Online abuse cases depend heavily on electronic records because the conduct may take place entirely through digital communication.
Chain of custody: Investigators must demonstrate that seized devices and extracted evidence were handled without tampering.
Bharatiya Sakshya Adhiniyam: The current law governing evidence is the Bharatiya Sakshya Adhiniyam, 2023. The newspaper report notes the importance of statutory certification and documentation for electronic records in these investigations.
Attribution issue: Defence challenges may focus not on whether illegal material exists but on whether the prosecution has proved that the accused was the person who knowingly accessed, distributed or controlled it.
What role do POCSO Special Courts play?
Designation: Section 28 provides for Special Courts to ensure speedy trial of POCSO offences.
IT Act jurisdiction: Section 28(3) specifically empowers such courts to try Section 67B IT Act offences relating to publication or transmission of sexually explicit material depicting children.
Child-friendly procedure: POCSO requires protection of the child's identity, limits aggressive questioning and provides mechanisms such as in-camera trials and protective arrangements when a child gives evidence.
Objective: The justice process should not itself inflict secondary trauma on the child.
What did the Supreme Court hold in Just Rights for Children Alliance v. S. Harish?
Background: The case arose after the Madras High Court had quashed criminal proceedings involving Section 67B of the IT Act and Section 15 of POCSO.
Supreme Court ruling: The Court restored a wider interpretation of the child-protection framework and explained that constructive possession can be sufficient under Section 15 where the person knowingly exercises control over illegal material.
Three Section 15 offences: The Court explained that Section 15 contains three distinct forms of criminal conduct associated with different intentions.
Reporting duty: It stressed that the statutory reporting architecture under Sections 19 and 20 is central to combating online sexual exploitation.
Terminology: The Court recommended use of the expression CSEAM instead of terminology that may normalise or trivialise sexual exploitation of children.
What is constructive possession in simple terms?
Physical possession: A prohibited file is downloaded and stored on a person's device.
Constructive possession: The person may not physically store it but nevertheless knowingly has control over the material—for instance the power to view, save, forward or otherwise exercise dominion over it.
Supreme Court approach: Digital technology cannot be allowed to create a loophole where illegal material is deliberately streamed or accessed through links merely to avoid permanent storage.
Mens rea safeguard: Knowledge and control remain crucial. Accidentally encountering an unknown link is conceptually different from deliberately and repeatedly seeking out prohibited material.
What is the role of the National Commission for Protection of Child Rights?
Statutory basis: The National Commission for Protection of Child Rights (NCPCR) is constituted under Section 3 of the Commissions for Protection of Child Rights Act, 2005.
Functions: It reviews child-protection safeguards, examines violations, investigates factors contributing to exploitation and recommends remedial action.
Online-abuse work: Its annual reports show earlier engagement with Instagram, Facebook and YouTube over identifying and reporting CSAM and compliance with Section 19 of POCSO.
Latest development: Separately from NHRC's proceedings, contemporary reporting indicates that NCPCR has also sought Meta India's response over the recent allegations.
How are NHRC and NCPCR different?
NHRC: A national human-rights institution established under the Protection of Human Rights Act, 1993 with a broad mandate covering human rights generally.
NCPCR: A specialised statutory child-rights commission under the CPCR Act, 2005.
Overlap: Online sexual exploitation of children can simultaneously involve child rights and broader human rights, allowing different institutions to examine the issue within their respective mandates.
Why is platform advertising different from ordinary user-generated content?
Financial relationship: In ordinary hosting, a user may publish content independently. Paid advertisements involve a commercial transaction with the platform.
Review systems: Advertising generally passes through eligibility, content and targeting systems.
Algorithmic delivery: The platform determines which users are likely to see the advertisement.
Monetisation: The platform itself receives advertising revenue.
Regulatory question: The greater the platform's role in approval, targeting and amplification, the stronger the argument that regulators must examine whether traditional assumptions about passive intermediary conduct remain adequate.
Caution: This does not mean every advertisement automatically destroys intermediary protection. The legal issue depends on statutory interpretation and facts.
How does end-to-end encryption complicate CSAM investigations?
Encryption: In an end-to-end encrypted service, message content is ordinarily readable only by communicating users and not by the intermediary transporting the message.
Protection: Encryption protects privacy, cybersecurity, journalists, businesses and ordinary citizens.
Investigative difficulty: It may also reduce platforms' ability to scan private message contents and make conventional server-side detection more difficult.
Governance dilemma: Policy must balance child protection and effective investigation with privacy, cybersecurity and risks of weakening encryption for all users.
UPSC approach: Avoid the false choice that either privacy or child safety must be completely sacrificed. The policy problem is designing proportionate investigative and platform safeguards.
Why is AI-generated CSAM an emerging challenge?
Known-content detection: Traditional systems often detect copies of previously identified material through hash matching.
Generative AI: AI can create entirely new synthetic imagery that has no existing matching hash.
Victimisation: Synthetic sexual depictions involving identifiable children can cause serious reputational, psychological and dignity-related harm even if no original photograph depicts actual physical abuse.
Scale: Automated generation can produce huge quantities quickly.
Regulation: India's 2026 IT Rules amendments specifically recognise the problem by requiring relevant technical safeguards against generation of illegal CSEAM.
What constitutional values are involved?
Article 21: The protection of life and personal liberty encompasses dignity and privacy, both centrally implicated in sexual exploitation.
Article 15(3): The Constitution permits the State to make special provisions for women and children.
Article 39(f): The Directive Principles call for children to develop in conditions of freedom and dignity and to be protected against exploitation and moral and material abandonment.
Article 51A(e): The Fundamental Duties include renouncing practices derogatory to the dignity of women, relevant to the wider constitutional culture surrounding sexual exploitation.
Child-centred interpretation: POCSO translates the constitutional commitment to protect children's dignity and bodily autonomy into a specialised penal and procedural framework.
What international child-rights framework is relevant?
UN Convention on the Rights of the Child: India is a party to the Convention on the Rights of the Child (CRC).
The Convention requires States to protect children from sexual exploitation and sexual abuse.
POCSO linkage: The preambular framework of POCSO explicitly recognises international obligations to protect children from exploitative sexual practices and involvement in sexual performances and material.
Cross-border challenge: Because major platforms, cloud servers and reporting organisations may operate outside India, tackling CSAM inevitably requires international cooperation.
What are the biggest weaknesses in India's present reporting system?
Alert-to-action gap: Huge volumes of automated alerts must pass through several institutions before reaching investigators.
Data quality: Some reports contain detailed information while others may be incomplete.
Jurisdiction delays: Identifying the correct police station can take time.
Digital-forensics capacity: Smaller police units may lack specialised staff and equipment.
Age verification: Investigators must determine whether the depicted person is a child.
Platform responsiveness: Cross-border requests for account information can delay cases.
Encryption and anonymity: Offenders may use encrypted channels, disposable accounts, VPNs or anonymous payment methods.
AI-generated content: Detection systems trained on previously known files can struggle against novel synthetic material.
Victim identification: Discovering an illegal file does not necessarily reveal who the abused child is or where the original offence occurred.
Why can the CyberTipline reporting chain create delays?
International detour: A platform may detect material in India but send the report first to a US-based organisation.
Central routing: The alert then enters Indian central agencies.
State allocation: It must subsequently be assigned to State or district authorities.
Police verification: Local authorities still have to verify jurisdiction, evidence and the suspected offence.
Structural lesson: Centralisation can improve coordination and deduplication, but excessive layers can reduce speed.
The article notes concern that even cases involving an Indian victim, offender and platform activity can pass through several institutional stages before reaching the police unit capable of taking action.
What does this case reveal about the future of intermediary regulation?
Old question: Did the platform merely host content created by another person?
New question: Did the platform's automated systems recommend, amplify, transform, generate, approve, target or monetise the content?
Emerging doctrine: Digital regulation is moving from simple “content hosting” towards systemic accountability for platform design.
Risk-based regulation: Regulators may increasingly examine whether platforms have adequate safeguards at the advertising, recommendation and AI-generation stages instead of waiting until harmful content has already spread.
UPSC significance: The issue sits at the intersection of fundamental rights, criminal law, platform regulation, artificial intelligence and administrative capacity.
What are the main competing concerns policymakers must balance?
Child safety: Detecting abuse and stopping circulation must be the highest immediate priority.
Due process: A CyberTipline alert cannot automatically establish guilt.
Privacy: Mass surveillance of every user's communications would raise serious constitutional and cybersecurity issues.
Innovation: Regulation should not prohibit legitimate AI and digital services merely because they can be misused.
Safe harbour: Intermediary protection remains important for the functioning of the open internet, but it should not become a shield for deliberate non-compliance.
Law-enforcement capacity: Imposing more reporting duties without strengthening police capacity could simply increase the backlog of alerts.
Why is this issue important for UPSC?
Polity and governance: POCSO, IT Act, NHRC, NCPCR and intermediary regulation.
Social justice: Protection of children from sexual exploitation and abuse.
Internal security: Cybercrime, encrypted platforms, digital forensics and cross-border data.
Science and technology: AI-generated content, algorithmic recommendation and hash-based detection.
Ethics: Technology companies face questions of corporate responsibility when business models based on engagement or advertising interact with grave human-rights violations.
Mains relevance: The central governance problem is not merely absence of law. India already has stringent legal provisions. The more difficult challenge is conversion of legal duties and digital alerts into rapid, accountable enforcement.
Way Forward
Establish a faster, standardised pipeline linking platforms, NCMEC-generated alerts, NCRB, I4C and State police so urgent child-protection cases are not delayed by unnecessary institutional routing.
Develop a national risk-based triage system that prioritises CyberTipline reports according to immediacy of harm, identifiable victims, live abuse, trafficking indicators and strength of technical evidence.
Strengthen cyber-forensics capacity at State and district levels, including trained investigators, specialised laboratories and continuous training in platform data, IP attribution and electronic evidence.
Create clear statutory and regulatory guidance on how Section 19 POCSO reporting obligations apply to social-media companies and other digital intermediaries operating in India.
Ensure that platforms cannot treat internal moderation or removal of illegal content as a substitute for legally mandated reporting to competent authorities.
Clarify intermediary safe-harbour rules for situations where automated systems materially participate in approving, generating, recommending, amplifying or monetising unlawful content.
Require stronger pre-publication safeguards for paid advertising because paid advertisements involve a closer commercial and algorithmic relationship between advertiser and platform than ordinary user posts.
Develop privacy-respecting technologies such as robust hashing, perceptual matching and victim-identification tools while avoiding indiscriminate surveillance of lawful communications.
Establish specialised capacity for detecting AI-generated CSEAM, as conventional hash-matching is insufficient against newly generated synthetic material.
Improve cross-border law-enforcement cooperation and legal-assistance arrangements because platforms, servers, offenders and victims may be located in different jurisdictions.
Integrate online child-protection training within police, prosecution, schools and child-welfare institutions and increase awareness about anonymous reporting through the National Cyber Crime Reporting Portal.
Strengthen rehabilitation, psychological support and victim identification because success should not be measured only by content takedowns or FIR numbers, but also by identification and protection of children who have suffered abuse.
UPSC Previous Year Questions (PYQs)
No directly relevant verified UPSC Mains PYQ is available.
UPSC Mains Practice Questions
India possesses a substantial legal framework against online sexual exploitation of children, yet a large gap persists between detection of Child Sexual Abuse Material and successful criminal enforcement. Discuss the causes of this enforcement gap. Examine how intermediary liability, mandatory reporting and artificial intelligence are reshaping child-protection governance in India.
UPSC Prelims Practice MCQs
- Which of the following best describes the core governance problem highlighted by the present controversy?09 Sept 2026
- India is a party to which major international convention dealing comprehensively with children's rights?09 Sept 2026
- Article 39(f) of the Constitution is associated with:09 Sept 2026
- Which Constitutional provision permits the State to make special provisions for children?09 Sept 2026
- With reference to algorithmic recommendation systems, which of the following best describes the current regulatory concern?09 Sept 2026
- Why can end-to-end encryption complicate investigations?09 Sept 2026
- Which of the following can be used in identifying a suspect in an online CSAM case?1.IP records2.Platform account information3.SIM and telecom records4.Financial transactionsSelect the correct answer using the code given below:09 Sept 2026
- Consider the following statements regarding a CyberTipline report:1.It automatically proves commission of a crime.2.Investigators may use IP logs and account details contained in the report.3.Jurisdiction and identity of the responsible person may require additional investigation.Which of the statements given above are correct?09 Sept 2026
- The National Cyber Crime Reporting Portal allows anonymous reporting particularly in relation to:09 Sept 2026
- Which statement correctly distinguishes NHRC from NCPCR?09 Sept 2026
- The National Human Rights Commission is established under:09 Sept 2026
- The National Commission for Protection of Child Rights is constituted under:09 Sept 2026
- POCSO Special Courts may also try offences under which provision of the IT Act relating to sexually explicit material depicting children?09 Sept 2026
- Which Section of the POCSO Act provides for designation of Special Courts?09 Sept 2026
- “Constructive possession” in the context of digital CSAM means:09 Sept 2026
- Which doctrine was significantly applied by the Supreme Court in Just Rights for Children Alliance v. S. Harish?09 Sept 2026
- The Supreme Court judgment Just Rights for Children Alliance v. S. Harish is primarily associated with interpretation of:09 Sept 2026
- Which of the following is a limitation of conventional file-hash matching?09 Sept 2026
- In investigations relating to CSAM, digital hash values are particularly useful for:09 Sept 2026
- What is a digital hash value?09 Sept 2026
- Which of the following Indian institutions process or coordinate CyberTipline-related reports?1.National Crime Records Bureau2.Indian Cyber Crime Coordination Centre3.State and district police authoritiesSelect the correct answer using the code given below:09 Sept 2026
- A CyberTipline report is best described as:09 Sept 2026
- The CyberTipline is operated by:09 Sept 2026
- The 2026 amendments to the IT Rules concerning synthetically generated information specifically require safeguards against:09 Sept 2026
- The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules were originally notified in:09 Sept 2026
- With reference to intermediary safe harbour in India, which of the following statements is correct?09 Sept 2026
- Which Section of the Information Technology Act provides conditional exemption from liability to intermediaries?09 Sept 2026
- Section 67B of the Information Technology Act, 2000 primarily relates to:09 Sept 2026
- Section 15 of the POCSO Act is associated with:09 Sept 2026
- Which Section of the POCSO Act deals with punishment for failure to report or record a case?09 Sept 2026
- Under Section 19 of the POCSO Act, information concerning an offence may be given to:09 Sept 2026
- Which Section of the POCSO Act contains the general mandatory reporting obligation?09 Sept 2026
- The POCSO Act primarily deals with:09 Sept 2026
- The Protection of Children from Sexual Offences Act, 2012 defines a child as:09 Sept 2026
- The Indian Cyber Crime Coordination Centre functions under:09 Sept 2026
Sources
National Human Rights Commission — Human Rights Advisory for Protection of the Rights of Children against Production, Distribution and Consumption of Child Sexual Abuse Material (CSAM): https://nhrc.nic.in/activities/other_advisories
National Human Rights Commission — Earlier suo motu proceedings concerning reported increase in Child Sexual Abuse Material on social media: https://nhrc.nic.in/media/press-release/nhrc-notices-to-the-centre-states-union-territories-over-the-reported-increase-250-300-in-child-sexual-abuse-material-csam-on-social-media-in-india
India Code — Protection of Children from Sexual Offences Act, 2012: https://www.indiacode.nic.in/handle/123456789/17804
India Code — Official PDF of the Protection of Children from Sexual Offences Act, 2012: https://upload.indiacode.nic.in/showfile?actid=AC_CEN_13_14_00005_201232_1517807323686&filename=a2012-32.pdf&type=actfile
India Code — Information Technology Act, 2000: https://www.indiacode.nic.in/handle/123456789/15442
Ministry of Electronics and Information Technology — Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, updated amendments: https://www.meity.gov.in/documents/act-and-policies/information-technology-intermediary-guidelines-and-digital-media-ethics-code-rules-2021-it-rules-2021-IjM5QjMtQWa
Ministry of Electronics and Information Technology — Consolidated amended IT Rules including provisions concerning synthetically generated information: https://www.meity.gov.in/static/uploads/2026/04/93820275c4f00a64fd82884731b6dec4.pdf
Supreme Court of India — Just Rights for Children Alliance & Anr. v. S. Harish & Ors., 2024 INSC 716: https://api.sci.gov.in/supremecourt/2024/8562/8562_2024_1_1501_56073_Judgement_23-Sep-2024.pdf
National Commission for Protection of Child Rights — About NCPCR and statutory mandate: https://www.ncpcr.gov.in/public/about-ncpcr
National Commission for Protection of Child Rights — Annual Report 2023-24, including CSAM programme and platform engagement: https://ncpcr.gov.in/uploads/175637028068b0156839895_english.pdf
National Cyber Crime Reporting Portal / I4C — Online reporting system for cybercrime relating to women and children: https://www.cybercrime.gov.in/Accept.aspx
The Indian Express — “How Instagram ads row underlines India’s problem with reporting child abuse material”: https://indianexpress.com/article/explained/explained-law/nhrc-notice-meta-instagram-ads-pocso-rules-10863594/
The Tribune — NHRC questions Meta’s AI role and intermediary status in child-abuse advertisement controversy: https://www.tribuneindia.com/news/delhi/nhrc-questions-metas-ai-role-in-child-abuse-ads/
NDTV — NCPCR summons Meta India chief over Instagram advertisements allegedly linked to child sexual abuse material: https://www.ndtv.com/india-news/meta-india-chief-summoned-over-instagram-child-abuse-ad-report-12019162